Vulnerability record · CVE-2018-12465 · published 29 June 2018
CVE-2018-12465: Micro Focus Secure Messaging Gateway web admin OS command injection
Microfocus · Secure Messaging Gateway
The web administration component of Micro Focus Secure Messaging Gateway (SMG) before version 471 fails to neutralize OS command input, allowing command injection (CWE-77/CWE-78). A privileged authenticated user can run arbitrary OS commands on the SMG server, and the flaw can be chained with CVE-2018-12464 to reach unauthenticated remote code execution.
Description
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that used GWAVA product name (i.e. GWAVA 6.5).
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with high confidentiality, integrity and availability impact, very high EPSS, public exploit code, and a chain to unauthenticated RCE, though exploitation requires privileged access unless chained.
What it is
The web administration component of Micro Focus Secure Messaging Gateway (SMG) before version 471 fails to neutralize OS command input, allowing command injection (CWE-77/CWE-78). A privileged authenticated user can run arbitrary OS commands on the SMG server, and the flaw can be chained with CVE-2018-12464 to reach unauthenticated remote code execution.
Impact
An attacker with privileged web admin access gains arbitrary OS command execution on the SMG server, leading to full compromise of the appliance and any data or credentials it handles. Chained with CVE-2018-12464, the same code execution is reachable without authentication.
Attack surface
Reached over the network through the SMG web administration interface (CVSS AV:N). The vector requires high privileges (PR:H) and no user interaction (UI:N), so a valid privileged admin account is needed unless chained with CVE-2018-12464.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.80021, 99.6th percentile) and public exploit code exists on Exploit-DB (45083) plus a detailed write-up, indicating active interest and easy weaponization.
What to do
- Upgrade Secure Messaging Gateway to version 471 or later; versions prior to 471 are affected.
- If immediate patching is not possible, restrict network access to the SMG web administration interface to trusted management networks.
- Enforce least privilege and strong authentication for SMG admin accounts, and audit for unnecessary privileged users.
- Monitor and apply the fix for CVE-2018-12464 as well, since the two flaws chain into unauthenticated RCE.
Detection
- Monitor SMG web admin logs for unusual requests or parameters that could carry shell metacharacters.
- Alert on unexpected child processes spawned by the SMG web server or application service.
- Watch for outbound connections or command-and-control traffic originating from the SMG server.
- Review authentication logs for anomalous privileged admin logins or new admin account creation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-12465 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-12465), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.